Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 18 Apr 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored XSS in EnterpriseDB Postgres Enterprise Manager via Manage Charts Menu |
Tue, 10 Feb 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:enterprisedb:postgres_enterprise_manager:*:*:*:*:*:*:*:* |
Mon, 19 Jan 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Enterprisedb
Enterprisedb postgres Enterprise Manager |
|
| Vendors & Products |
Enterprisedb
Enterprisedb postgres Enterprise Manager |
Fri, 16 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 16 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with access to the Manage Charts menu to inject arbitrary JavaScript when creating a new chart, which is then executed by any user accessing the chart. By default only the superuser and users with pem_admin or pem_super_admin privileges are able to access the Manage Charts menu. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: EDB
Published:
Updated: 2026-01-16T16:49:37.156Z
Reserved: 2026-01-14T16:55:03.874Z
Link: CVE-2026-0949
Updated: 2026-01-16T16:49:28.968Z
Status : Analyzed
Published: 2026-01-16T17:15:54.047
Modified: 2026-02-10T17:25:39.597
Link: CVE-2026-0949
No data.
OpenCVE Enrichment
Updated: 2026-04-18T05:45:38Z